cbcvebase.
CVE-2016-4462
published 2017-08-30

CVE-2016-4462: By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are…

high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01

Affected

22 ranges
VendorProductVersion rangeFixed in
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apache_software_foundationapache_ofbiz
apache_software_foundationapache_ofbiz
apache_software_foundationapache_ofbiz